CVE-2026-15186
CVE-2026-15186 is a medium-severity vulnerability with a CVSS 3.x base score of 6.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-99.
Key facts
- Severity: Medium (CVSS 3.x base score 6.3)
- CVSS v2: 6.5
- CVSS v4: 2.1
- EPSS exploit prediction: 0% (15th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-99
- Published:
- Last modified:
Description
A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Frequently asked questions
- What is CVE-2026-15186?
- A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.
- How severe is CVE-2026-15186?
- CVE-2026-15186 has a CVSS 3.x base score of 6.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-15186 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (15th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-15186?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-15186 published?
- CVE-2026-15186 was published on 2026-07-09.
References
- https://github.com/macrozheng/mall/
- https://github.com/macrozheng/mall/issues/977
- https://vuldb.com/cve/CVE-2026-15186
- https://vuldb.com/submit/851347
- https://vuldb.com/vuln/377112
- https://vuldb.com/vuln/377112/cti
Other CWE-99 vulnerabilities
- CVE-2025-43491 — Critical (CVSS 9.8): A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the…
- CVE-2017-5159 — Critical (CVSS 9.8): An issue was discovered on Phoenix Contact mGuard devices that have been updated to Version 8.4.0. When updating an…
- CVE-2025-2410 — Critical (CVSS 9.1): Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if…
- CVE-2025-0756 — Critical (CVSS 9.1): Overview The product receives input from an upstream component, but it does not restrict or incorrectly…
- CVE-2024-57971 — Critical (CVSS 9.1): DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that…
- CVE-2024-5706 — High (CVSS 8.8): The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input…